From 25b786915c18b0b8eb355a4296e0d3f6920c2925 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Torjus=20H=C3=A5kestad?= Date: Sat, 6 Dec 2025 11:02:43 +0100 Subject: [PATCH] auth01: add lldap password to secrets --- secrets/auth01/secrets.yaml | 12 ++++-------- services/lldap/default.nix | 12 +++++++++++- 2 files changed, 15 insertions(+), 9 deletions(-) diff --git a/secrets/auth01/secrets.yaml b/secrets/auth01/secrets.yaml index 9979cbd..6a32419 100644 --- a/secrets/auth01/secrets.yaml +++ b/secrets/auth01/secrets.yaml @@ -2,11 +2,8 @@ authelia_ldap_password: ENC[AES256_GCM,data:x2UDMpqQKoRVSlDSmK5XiC9x4/WWzmjk7cwt authelia_jwt_secret: ENC[AES256_GCM,data:9ZHkT2o5KZLmml95g8HZce8fNBmaWtRn+175Gaz0KhsndNl3zdgGq3hydRuoZuEgLVsherJImVmb5DQAZpv04lUEsDKCYeFNwAyYl4Go2jCp1fI53fdcRCKlNVZA37pMi4AYaCoe8vIl/cwPOOBDEwK5raOBnklCzVERoO0B8a0=,iv:9CTWCw0ImZR0OSrl2znbhpRHlzAxA5Cpcy98JeH9Z+Y=,tag:L+0xKqiwXTi7XiDYWA1Bcw==,type:str] authelia_storage_encryption_key_file: ENC[AES256_GCM,data:RfbcQK8+rrW/Krd2rbDfgo7YI2YvQKqpLuDtk5DZJNNhw4giBh5nFp/8LNeo8r39/oiJLYTe6FjTLBu72TZz2wWrJFsBqjwQ/3TfATQGdLUsaXXRDr88ezHLTiYvEHIHJhUS5qsr7VMwBam5e7YGWBe5sGZCE/nX41ijyPUjtOY=,iv:sayYcAC38cApAtL+cDhgGNjWaHn+furKRowKL6AmfdU=,tag:1IZpnlpvDWGLLpZyU9iJUw==,type:str] authelia_session_secret: ENC[AES256_GCM,data:4PaLv4RRA7/9Z8QzETXLwo3OctJ0mvzQkYmHsGGF97nq9QeB3eo0xj4FyuCbkJGGZ/huAyRgmFBTyscY3wgxoc4t+8BdlYcSbefEk1/xRFjmG8ooXLKhvGJ5c6t72KJRcqsEGTiC0l9CFJWQ2qYcjM4dPwG8z0tjUZ6j25Zfx4M=,iv:QORJkf0w6iyuRHM/xuql1s7K75Qa49ygq+lwHfrm9rk=,tag:/HZ/qI80fKjmuTRwIwmX8g==,type:str] +ldap_user_pass: ENC[AES256_GCM,data:954+/DX5EvXIbPYvhVIA5w==,iv:sl6XxzmXyKpGqzZSY/S6qpFD2GVCqrx+JaryblUE3ec=,tag:vZEtFrqrCIKH12MQf6LAAg==,type:str] sops: - kms: [] - gcp_kms: [] - azure_kv: [] - hc_vault: [] age: - recipient: age1lznyk4ee7e7x8n92cq2n87kz9920473ks5u9jlhd3dczfzq4wamqept56u enc: | @@ -26,8 +23,7 @@ sops: RW5HRjA3cERCUU1CVWZhck12SGhTRUkK6k/zQ87TIETYouRBby7ujtwgpqIPKKv+ 2aLJW6lSWMVzL/f3ZrIeg12tJjHs3f44EXR6j3tfLfSKog2iL8Y57w== -----END AGE ENCRYPTED FILE----- - lastmodified: "2025-04-01T21:37:33Z" - mac: ENC[AES256_GCM,data:4stf2UFt1ogH8pIJCUwMvbXG7YzyehbDEi6Qsfi5s3Kmx/AQAC6SpE31HL3qgYNdi10vbZEVH1lrFljPWs4YdnevzM2z9l3mfiR5D10vp2z/Nvw/+IDNheXxQfgO82QdVZ6qfo83zxYPoda+PmdFatmHTB00V9lNm6DF4unRy60=,iv:byyo1297YoxFO6S9TVzlPHR082IugZHSHCiT5sZE2T0=,tag:dtSxGNVxjR77gnegIHw1Sw==,type:str] - pgp: [] + lastmodified: "2025-12-06T09:59:50Z" + mac: ENC[AES256_GCM,data:ioEp5RORyWx0WWReO9lqJYN6Pm9vFAmPfiYNDfcNjEgPDWsC7FSoCX0GjKWSsSOl2sfKmRPh/So1nTh2GOOO8e8DpucN3Daeu2GJs5XcbyJzdXSkgAsiPQp+FSz0ZIGLwlRQ+a1qz+SowEc7KAr8mguQ7+3x26OaLxKxJbX6Wds=,iv:nC+kELG1st0wNr20ty+uEcBLMSbGTOhe6eK8IpHmsqo=,tag:wSTee6q6FdNJhQ4keK2I6g==,type:str] unencrypted_suffix: _unencrypted - version: 3.9.4 + version: 3.11.0 diff --git a/services/lldap/default.nix b/services/lldap/default.nix index 750e054..a29914f 100644 --- a/services/lldap/default.nix +++ b/services/lldap/default.nix @@ -1,11 +1,21 @@ -{ ... }: +{ config, ... }: { + sops.secrets.lldap_user_pass = { + format = "yaml"; + key = "lldap_user_pass"; + sopsFile = ../../secrets/auth01/secrets.yaml; + restartUnits = [ "lldap.service" ]; + owner = "lldap"; + group = "lldap"; + }; + services.lldap = { enable = true; settings = { ldap_base_dn = "dc=home,dc=2rjus,dc=net"; ldap_user_email = "admin@home.2rjus.net"; ldap_user_dn = "admin"; + ldap_user_pass_file = config.sops.secrets.authelia_ldap_password.path; ldaps_options = { enabled = true; port = 6360;